No. An individual SPRight is a granular IdentityIQ product right, but roles do not normally grant an arbitrary standalone SPRight directly as a role entitlement. IdentityIQ groups SPRights into Capabilities , which provide logical collections of rights associated with administrative or functional job responsibilities.
The Role Editor provides a Granted IdentityIQ User Rights section where an engineer can associate IdentityIQ capabilities and scopes with a role. When that role is assigned and role provisioning is processed through Identity Refresh, the corresponding capabilities and scopes can be granted to the identity. This is the supported role-level abstraction.
The distinction matters because an SPRight controls granular access to specific IdentityIQ UI functions, tools, pages, or operations, while a Capability groups one or more SPRights into a maintainable authorization construct. Directly treating a single SPRight as an ordinary role option bypasses the intended rights-to-capability model.
Therefore, although a role can grant IdentityIQ user rights indirectly through configured capabilities, the proposed statement that the role is configured to include a single SPRight object is not the valid role configuration model.
References/topics: IdentityIQ Engineer — SPRight, Capability, Granted IdentityIQ User Rights, Role Editor, authorization model.
=======
Submit